EP3796107A1 - Système de guidage et procédé de gestion des certificats - Google Patents

Système de guidage et procédé de gestion des certificats Download PDF

Info

Publication number
EP3796107A1
EP3796107A1 EP19197796.6A EP19197796A EP3796107A1 EP 3796107 A1 EP3796107 A1 EP 3796107A1 EP 19197796 A EP19197796 A EP 19197796A EP 3796107 A1 EP3796107 A1 EP 3796107A1
Authority
EP
European Patent Office
Prior art keywords
registration service
component
specific information
central
certification
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Withdrawn
Application number
EP19197796.6A
Other languages
German (de)
English (en)
Inventor
Benjamin Lutz
Anna Palmin
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Siemens AG
Siemens Corp
Original Assignee
Siemens AG
Siemens Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Siemens AG, Siemens Corp filed Critical Siemens AG
Priority to EP19197796.6A priority Critical patent/EP3796107A1/fr
Publication of EP3796107A1 publication Critical patent/EP3796107A1/fr
Withdrawn legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G05CONTROLLING; REGULATING
    • G05BCONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
    • G05B9/00Safety arrangements
    • G05B9/02Safety arrangements electric
    • GPHYSICS
    • G05CONTROLLING; REGULATING
    • G05BCONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
    • G05B19/00Program-control systems
    • G05B19/02Program-control systems electric
    • G05B19/04Program control other than numerical control, i.e. in sequence controllers or logic controllers
    • G05B19/042Program control other than numerical control, i.e. in sequence controllers or logic controllers using digital processors
    • G05B19/0428Safety, monitoring
    • GPHYSICS
    • G05CONTROLLING; REGULATING
    • G05BCONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
    • G05B19/00Program-control systems
    • G05B19/02Program-control systems electric
    • G05B19/418Total factory control, i.e. centrally controlling a plurality of machines, e.g. direct or distributed numerical control [DNC], flexible manufacturing systems [FMS], integrated manufacturing systems [IMS] or computer integrated manufacturing [CIM]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/126Applying verification of the received information the source of the received data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • GPHYSICS
    • G05CONTROLLING; REGULATING
    • G05BCONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
    • G05B2219/00Program-control systems
    • G05B2219/30Nc systems
    • G05B2219/36Nc in input of data, input key till input tape
    • G05B2219/36542Cryptography, encrypt, access, authorize with key, code, password
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02PCLIMATE CHANGE MITIGATION TECHNOLOGIES IN THE PRODUCTION OR PROCESSING OF GOODS
    • Y02P90/00Enabling technologies with a potential contribution to greenhouse gas [GHG] emissions mitigation
    • Y02P90/02Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS]

Definitions

  • the present invention relates to a control system for a process plant and a method for certificate management in a process plant.
  • a system can be composed, for example, of a large number of components, possibly networked with one another and / or interdependent, such as valves, sensors, actuators and / or the like.
  • (digital) certificates are usually used, which can be issued, distributed and checked within a corresponding control system.
  • a control system can, for example, be based on what is known as a public key infrastructure (PKI).
  • PKI public key infrastructure
  • control systems of heterogeneous plants usually have central software inventories in which identity and authenticity-creating data on the components, e.g. B. device certificates in the form of manufacturer certificates (Manufacturer Device Certificates), serial numbers and / or the like are stored. This data is usually stored manually in the software inventory when the system is planned or initialized.
  • a first aspect of the invention relates to a control system for a process plant, with a central registration service that is set up to check a certification application for a plant component on the basis of component-specific information, and a software inventory that is set up to store the component-specific information .
  • the control system has at least one local registration service which is set up to transmit the certification application from the system component to the central registration service.
  • the at least one local registration service is set up to send the component-specific information together with the certification application, in particular as part of the certification application to be transmitted to the central registration service.
  • the central registration service is set up to manage the software inventory on the basis of the component-specific information transmitted by the local registration service.
  • a certification application within the meaning of the invention is, in particular, a request from a, z. B. operational, certificate for a system component and is also referred to as Certificate Signing Request (CSR).
  • CSR Certificate Signing Request
  • Such a request can in particular contain at least one signature of the respective system component making the application, which can optionally be checked for validity by a registration service.
  • the certificate can allow the system component, for example, to communicate securely, in particular encrypted, with other system components.
  • a system component within the meaning of the invention is in particular a physical component or a component of the process engineering system implemented as software.
  • a system component can, for example, be a device or an application that z. B. runs as software on a server in the system.
  • a central software inventory within the meaning of the invention is in particular a digital catalog or a digital directory.
  • the software inventory preferably at least some of the system components can be recorded together with the respective component-specific information. If necessary, certification paths called “trust chains” can also be stored in the software inventory, which represent a chain of certificates.
  • the software inventory can in particular be designed as a database or a list.
  • Management of a software inventory within the meaning of the invention is, in particular, maintenance of the software inventory.
  • a modification of the software inventory can, for example, be carried out as part of the administration.
  • Management of the software inventory preferably includes adding, Changing and / or deleting entries or data records in the inventory.
  • One aspect of the invention is based on the approach of adding additional information regarding the applying system component to a certification application submitted by a system component, in particular when forwarding such an application from a local registration service to a central or cross-system registration service of a process engineering system.
  • the component-specific information can in particular be transmitted to the central registration service as part of the forwarded certification application.
  • the component-specific information is preferably at least partially information which enables the certification application to be checked by the central registration service, in particular which is necessary for checking.
  • the component-specific information can include so-called meta information, which describes, for example, the role of the system component in its local system environment, for example within an autonomously functioning and secured system segment, or the networking of the system components with other system components.
  • the central registration service is preferably set up to store the component-specific information in a particularly central or cross-system software inventory and thus make it available, for example, for further future checks of incoming certification applications or for a centrally initiated renewal of certificates .
  • the software inventory of a control system for such a certificate management can in particular be managed fully automatically by the central registration service, ie without manual or semi-manual input by a user being necessary.
  • the central registration service is preferably set up to manage the software inventory dynamically, ie for example the software inventory during operation to keep the system up to date. This makes it z. B. possible to provide the correct component-specific information in the software inventory even when a system component is replaced by a replacement component and to correctly check an, in particular initial, certification application for the replacement component.
  • the central registration service is set up to update, in particular component-specific, information already stored in the software inventory on the basis of the transmitted component-specific information.
  • the central registration service can be set up to change, supplement and / or expand information that has already been stored. It is conceivable, for example, that in the case of a changed project planning, according to which the system component has to communicate at least partially with other and / or additional components, the corresponding information stored in the software inventory is adapted. This enables a permanently reliable examination of certificate applications by the central registration service.
  • the central registration service is set up to create a new data record on the basis of the transmitted component-specific information for a system component for which no, in particular component-specific, information is yet stored in the software inventory.
  • the central registration service is preferably set up to include information contained in the certification application, for example a signature under the application and / or a device ID, which can be represented by a serial number, along with other information to take over component-specific information in the software inventory. This makes it possible to automatically fill an essentially empty software inventory, for example when the system is started up.
  • the central registration service is set up to compare the transmitted component-specific information with, in particular component-specific, information stored in the software inventory and to generate a corresponding signal when an inconsistency is detected. For example, if a device is mistakenly integrated into several projects, i. H. For example, when used in different processes, the central registration service can recognize this on the basis of the certification applications received in relation to the multiple projects, in particular the component-specific information transmitted and stored in the software inventory, and output a corresponding message. In complex systems in particular, this can reduce the risk of incorrect configuration of a system component.
  • the at least one local registration service is set up to subject the application for certification of the system component to a preliminary check on the basis of the component-specific information.
  • the local registration service can already check the admissibility of the certification application within a system segment, e.g. B. according to system segment-specific criteria or criteria specific to the transmission protocol used.
  • the at least one local registration service is preferably set up to forward the certification application together with the component-specific information to the central registration service as a function of a result of the test, in particular when the certification application is certified. In this way, applications that, for example, already turn out to be inadmissible within a system segment, can be filtered out early on and thus the data traffic within the control system can be reduced.
  • the at least one local registration service is set up to obtain the component-specific information from an administration device which is set up to administer the system component.
  • Management of a system component is understood to mean, in particular, a configuration and / or control of the system component.
  • the management device can be, for example, what is known as an engineering station, which includes the configuration of a system segment or its system components and thus enables its autonomous operation and protection.
  • the local registration service can preferably derive all the relevant component-specific information with regard to the check by the central registration service or also to the preliminary check itself. Access to information stored by the administrative device is particularly advantageous, since the administrative device is usually operated continuously and the information can thus be accessed at any time.
  • control system has an administration device with an interface, the interface, also referred to as an adapter, being set up to determine component-specific information, in particular the system component making the request, and to provide it for the at least one local registration service.
  • the interface can also be set up to process the information obtained for use by the local registration service, e.g. B. to be converted into a corresponding data format.
  • the interface can be designed in particular as an application, ie as software, and for diagnosing the system segment, in particular the system component making the request and / or its system environment, be set up.
  • An administrative device designed in this way makes it possible to compile the component-specific information if necessary, ie for example when requested by the local registration service.
  • the component-specific information contains a project affiliation, which can be documented, for example, by a project-specific device certificate, a network-specific identification feature and / or a functional characteristic, in particular of the system component making the application.
  • a project affiliation which can be documented, for example, by a project-specific device certificate, a network-specific identification feature and / or a functional characteristic, in particular of the system component making the application.
  • Such features also known as meta information, can be used to classify the submitting component in the system context in particular. For example, their function and / or the interaction with other system components can be determined. On this basis, a full examination of the application can be carried out by a registration service.
  • the compatibility and / or the authorization of the requesting component to communicate with another system component can be determined.
  • a functional characteristic ie information regarding the functions or function clusters provided by the system component, it can be determined, for example, whether the applying component needs the certificate applied for for a specific function at all.
  • Such functions can, for example, the monitoring and Control of processes running in the system and / or the diagnosis or maintenance of other system components.
  • the central registration service is set up to check a certification of the local registration service on the basis of information stored in the software inventory.
  • the central registration service can in particular be set up to check whether there is already an established trust relationship with the at least one local registration service.
  • a signing certificate from the local registration service can be or will be stored in the software inventory, on the basis of which the central registration service can determine the permissibility of the forwarding of a certification application by the local registration service.
  • a signature certificate possibly together with the associated trust chain, can be transmitted to the central registration service for storage in the software inventory, for example, when the system is initialized or at least the system segment assigned to the at least one local registration service or as part of a centrally initiated certificate rollout become.
  • the central registration service can then, for example, check a signature of the local registration service in the transmitted certification application.
  • the central registration service can in particular check whether the signature matches the certificate request, whether it was issued by the respective local registration service and / or whether it is trustworthy, i.e. H. whether it can be traced back to a central certification service on the basis of the chain of trust.
  • the trust in certificates that have been checked by the central registration service and then issued, in particular by a central certification service can be increased further.
  • the central registration service is preferably set up to process the software inventory as a function of a result of the examination of the certification of the local registration service to manage, in particular only to update information stored in the software inventory or to create a new data record if there is a trust relationship with the local registration service, ie the local registration service is or will be authenticated.
  • the at least one local registration service is set up to authenticate the certification request before it is transmitted to the central registration service.
  • the at least one local registration service can sign a certification application with a signing certificate, in particular a certification application that has been validated by it as part of a preliminary check.
  • the central registration service is preferably set up to only validate such certification applications and, for example, to forward them to a central certification service if such a signing certificate is available. This can further increase trust in the communication security in the control system.
  • the central registration service is set up to store information in the software inventory, in particular on the basis of the authenticated certification request, on the basis of which a certification of the at least one local registration service can be checked.
  • the information can include, for example, a signature certificate from the local registration service and / or a certification path (trust chain) to the signature certificate with which the local registration service signed the certification request.
  • trust chain a certification path
  • a second aspect of the invention relates to a method for certificate management in a process plant, comprising the steps: (i) Transmission, by a local registration service, of a certification application for a plant component together with component-specific information contained in the certification application in particular to one central registration service; (ii) management of a central software inventory in which the component-specific information can be stored by the central registration service on the basis of the transmitted component-specific information; and (iii) checking the certification application by the central registration service on the basis of the component-specific information stored in the software inventory.
  • the local registration service determines the component-specific information from the environment of the system component making the application.
  • an environment can in particular be a, preferably self-sufficient, functional and secured system segment of the system, which z. B. is spatially and / or technically separated, for example by a firewall, from other system segments.
  • the registration service preferably does not access the requesting component directly.
  • the local registration service can request or query the component-specific information from an administrative device that is set up to manage, in particular to configure and / or control, the system component making the request, in particular via a corresponding interface.
  • the component-specific information can be provided even if the component making the application is temporarily unavailable, for example shut down.
  • FIG 1 shows an example of a control system 1 for certificate management in a process plant.
  • the control system 1 has a central registration service 2 for checking a certification application submitted by one of the system components 3, a software inventory 4 for storing component-specific information, ie information relating to the respective system components 3 and, in the present example, two local registration services 5a, 5b for forwarding of the certification application from the respective system component 3 to the central registration service 2.
  • the central registration service 2 is set up to check the certification application on the basis of the, in particular component-specific, information stored in the software inventory 4 and to forward it to a central certification service 6 as a function of a result of the check, in particular when the certification application is validated issues the corresponding certificate for system component 3.
  • the central registration service 2 also set up to manage the software inventory 4 based on component-specific information that is transmitted to the central registration service 2 by one of the local registration services 5a, 5b together with the certification application. This enables the fully automatic and dynamic management of the software inventory 4.
  • the central registration service 2 and the local registration services 5 are preferably connected to one another via a network, for example a terminal bus 7.
  • System segments 1a, 1b of the system are preferably also connected to the terminal bus 7, with the system segments 1a, 1b being able to define so-called security cells, for example, through a spatial and / or data-technical separation, e.g.
  • a local registration service 5a, 5b is preferably assigned to each system segment 1a, 1b.
  • a management device 8 also referred to as an engineering station, can be provided per system segment 1a, 1b, which is connected to the system components 3 of the respective system segment 1a, 1b via a further network, for example a system bus 9 configured as Industrial Ethernet.
  • the administration devices 8 preferably include the project planning of the respective plant segment 1a, 1b, ie they are set up for the configuration and / or control of the plant components 3 of the respective plant segment 1a, 1b.
  • the management devices 8 and the system components 3, which are designed as user servers (operator station servers) in the present example, are preferably also connected to peripheral components 10, for example sensors, valves, actuators and / or the like, for controlling processes via the system bus 9.
  • the respective system component 3 can submit a corresponding certification application which is transmitted via the terminal bus 7 to the responsible local registration service 5a, 5b.
  • the local registration service 5a, 5b is preferably set up to then request the component-specific information on the system component 3 making the application from the respective administration device 8.
  • the management device 8 is preferably set up to determine this information with the aid of a corresponding interface 11 and to make it available to the requesting local registration service 5a, 5b.
  • the interface 11 can, for. B. be designed as an application and access the configuration of the plant segment 1a, 1b.
  • the interface 11 can derive meta information from the project planning, for example relating to the functionality of individual system components 3 and / or their interaction with other system components 3, and, if necessary, prepare it for use by the local registration service 5a, 5b or the central registration service 2.
  • the local registration services 5a, 5b can be set up to carry out a preliminary check of the respective certification application transmitted to them on the basis of the component-specific information provided by the administrative devices 8.
  • the certification application can, for example, according to a standard protocol, e.g. B. the certificate management protocol also referred to as Certificate Management Protocol (CMP) according to the RFC 4210 standard, via the terminal bus 7 to the central registration service 2 are transmitted.
  • CMP Certificate Management Protocol
  • the responsible local registration service 5a, 5b is preferably set up to convert the certification application into the standard protocol if the certification application from the system component 3 is made using another Standards, e.g. B. the Open Platform Communications (OPC) Unified Architecture (UA) GDS, is transmitted.
  • OPC Open Platform Communications
  • the local registration services 5a, 5b are preferably set up to transmit the component-specific information together with the respective certification application, in particular as part of the respective certification application, to the central registration service 2.
  • the application corresponds to an initial application for a certificate (bootstrapping)
  • the component-specific information is entered in the software inventory 4.
  • the component-specific information can thus form at least part of a new data record.
  • the central registration service 2 preferably searches for an entry in the software inventory 4 for the corresponding system component 3 and, if necessary, compares the transmitted component-specific information with information stored in the software inventory 4.
  • the central registration service 2 can then optionally update the information stored in the software inventory 4. This makes it possible to ensure that when certification applications are checked by the central registration service 2, current component-specific information is always available.
  • FIG 2 shows an example of a software inventory 4 that is part of a control system of a process engineering plant.
  • the software inventory 4 is designed as a database.
  • the database contains nine data records, each with seven data fields, each data record being shown in one line and assigned to a system component.
  • a local registration service 5a, 5b, 5c via which a certification application for the respective system component is transmitted to a central registration service be.
  • Each local registration service 5a, 5b, 5c is certified on the basis of a signature certificate in the software inventory 4, whereby a trust relationship with the local registration service 5a, 5b, 5c is established.
  • the certification is implemented here by an entry in the data fields 12a.
  • Data fields 12b indicate the manufacturer of the respective system component, while a serial number of the respective system component is stored in data fields 12d. Furthermore, manufacturer certificates are stored in data fields 12e, user certificates in data fields 12f and operational certificates in data fields 12g. Of course, other component-specific information can also be stored in the data fields.
  • the software inventory 4 can be dynamic, i. H. in the operation of the process plant, updated, in particular expanded, are.
  • a certification application is received by the central registration service
  • an already existing data record can be supplemented with further component-specific information.
  • a new data record can also be added when a local registration service 5a, 5b, 5c transmits a signature certificate to the central registration service to establish a trust relationship, in particular when the system or at least one system segment is commissioned.
  • the new data record only contains an entry in data field 12a. Later a certification application goes to a Plant components via this local registration service 5a, 5b, 5c at the central registration service, the data record can be expanded or updated as described.
  • FIG 3 shows an example of a method 100 for certificate management in a process plant.
  • a certification application is made by a system component, for example because the component wants to communicate with another system component in an encrypted manner and requires a corresponding certificate for this.
  • the system component transmits the certification application to a local registration service, which is preferably assigned to a system segment, part of which is the system component and which is secured against other segments of the system, for example by spatial separation and / or in terms of data.
  • the local registration service determines component-specific information, in particular meta information, which describes, for example, the function of the system components in the system segment and / or their interaction with other system components.
  • component-specific information z. B. also deal with certificates, which are required for communication between system components.
  • the local registration service When determining the information, the local registration service preferably does not access the relevant system component directly, but rather a system environment of the component.
  • the local registration service can access an administrative device that is set up to configure and / or control all system components in the system segment.
  • an administration device thus generally has the desired component-specific information or at least information from which the desired component-specific information can be derived.
  • the local registration service checks the certification application on the basis of the component-specific information that has been determined. For example, the local registration service can check whether a communication intended by the system component, for which the certificate is requested, is actually provided within the scope of a project planning. To sign the validation of the certification application, the local registration service can sign the certification application, for example with the aid of a signing certificate which is issued by a central certification service for the local registration service.
  • the certification application validated in this way is transmitted together with the component-specific information from the local registration service in a further method step S4 to a central registration service.
  • the local registration service can enrich the certification application with the component-specific information.
  • the central registration service uses this component-specific information, possibly after extraction from the transmitted certification application, in order to manage a software inventory.
  • the central registration service can, for example, compare the transmitted component-specific information with information stored in the software inventory and update or supplement the software inventory as a function of a result of the comparison.
  • the central registration service determines discrepancies or inconsistencies between the transmitted component-specific information and information stored in the software inventory, for example if, according to an entry in the software inventory for a further system component with which the requesting system component wants to communicate in accordance with the transmitted component-specific information, communication with the requesting system component is not allowed at all.
  • the central registration service can provide a corresponding Signal, for example in the form of a message to a user of the system, generate and / or output.
  • the central registration service checks the certification application on the basis of the information stored in the central software inventory. In particular, it can be checked whether there is a trust relationship with the transmitting local registration service, for example by authenticating the signature of the local registration service in the certification application on the basis of information stored in the software inventory. Depending on a result of the check, the central registration service can then validate the certification application, for example sign it, and forward it to the central certification service for issuing the requested certificate.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • General Physics & Mathematics (AREA)
  • Automation & Control Theory (AREA)
  • Physics & Mathematics (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • General Engineering & Computer Science (AREA)
  • Quality & Reliability (AREA)
  • Manufacturing & Machinery (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
EP19197796.6A 2019-09-17 2019-09-17 Système de guidage et procédé de gestion des certificats Withdrawn EP3796107A1 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
EP19197796.6A EP3796107A1 (fr) 2019-09-17 2019-09-17 Système de guidage et procédé de gestion des certificats

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
EP19197796.6A EP3796107A1 (fr) 2019-09-17 2019-09-17 Système de guidage et procédé de gestion des certificats

Publications (1)

Publication Number Publication Date
EP3796107A1 true EP3796107A1 (fr) 2021-03-24

Family

ID=68051604

Family Applications (1)

Application Number Title Priority Date Filing Date
EP19197796.6A Withdrawn EP3796107A1 (fr) 2019-09-17 2019-09-17 Système de guidage et procédé de gestion des certificats

Country Status (1)

Country Link
EP (1) EP3796107A1 (fr)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116882636A (zh) * 2023-09-05 2023-10-13 苏州浪潮智能科技有限公司 证书生命周期管理方法、装置、设备及存储介质

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1162781A2 (fr) * 2000-06-09 2001-12-12 TRW Inc. Système et procédé de génération d'un certificat de signature dans une infrastructure à clé publique
EP3402152A1 (fr) * 2017-05-08 2018-11-14 Siemens Aktiengesellschaft Gestion de certificat automatisée, en fonction de l'installation

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP1162781A2 (fr) * 2000-06-09 2001-12-12 TRW Inc. Système et procédé de génération d'un certificat de signature dans une infrastructure à clé publique
EP3402152A1 (fr) * 2017-05-08 2018-11-14 Siemens Aktiengesellschaft Gestion de certificat automatisée, en fonction de l'installation

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
ANONYMOUS: "Prozessleitsystem - Wikipedia", 4 May 2017 (2017-05-04), XP055397767, Retrieved from the Internet <URL:https://de.wikipedia.org/w/index.php?title=Prozessleitsystem&oldid=165188304> [retrieved on 20170810] *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116882636A (zh) * 2023-09-05 2023-10-13 苏州浪潮智能科技有限公司 证书生命周期管理方法、装置、设备及存储介质
CN116882636B (zh) * 2023-09-05 2024-01-16 苏州浪潮智能科技有限公司 证书生命周期管理方法、装置、设备及存储介质

Similar Documents

Publication Publication Date Title
EP3605253B1 (fr) Initialisation automatisée des infrastructures à clé publique
EP3985532A1 (fr) Gestion des certificats pour installations techniques
EP4147099A1 (fr) Système et procédé pour vérifier des composants d&#39;un système de contrôle industriel
DE102014111361A1 (de) Verfahren zum Betreiben einer Sicherheitssteuerung und Automatisierungsnetzwerk mit einer solchen Sicherheitssteuerung
EP3993339B1 (fr) Gestion des certificats dans une installation technique
EP3762845B1 (fr) Gestion des certificats relatif à un projet
EP4578140B1 (fr) Module technique sécurisé
EP2304558A1 (fr) Système et procédé de communication à distance entre un ordinateur central et une commande de machine
EP3796107A1 (fr) Système de guidage et procédé de gestion des certificats
EP1496664A2 (fr) Système, méthode et module de sécurité pour sécuriser l&#39;accèss d&#39;un utilisateur à au moins un composant d&#39;automatisation d&#39;un système d&#39;automatisation
DE102022101689A1 (de) Verfahren zur Änderung eines Ist-Zugangsschlüssels in einem Feldgerät der Automatisierungstechnik
DE102021127139A1 (de) Systeme und verfahren zum sicheren einschränken der fahrbarkeit eines fahrzeugs durch beeinträchtigte benutzer
WO2013041360A1 (fr) Système et procédé pour fournir un code de programme de commande
WO2020221523A1 (fr) Procédé d&#39;attribution de certificats, système de guidage, utilisation d&#39;un tel système, installation technique, composants d&#39;installation et utilisation d&#39;un fournisseur d&#39;identité
EP3836489B1 (fr) Attribution dynamique d&#39;unités d&#39;automatisation aux serveurs d&#39;automatisation
DE102020109294A1 (de) Verfahren zum Betrieb eines Systems
DE102016212755B3 (de) Ethernet-Fahrzeugbordnetz mit geschützter Konfigurierbarkeit
EP4254233A1 (fr) Procédé et système de mise en oeuvre sécurisée d&#39;applications de commande, hôte
EP3339994A1 (fr) Procédé de vérification d&#39;une attribution de mandat, produit-programme informatique et dispositif
EP4113928A1 (fr) Système de commande pour une installation technique et procédé d&#39;émission d&#39;une demande de certificat pour un composant d&#39;installation
EP4432602A1 (fr) Procédé de présentation d&#39;un certificat et site d&#39;enregistrement mis en uvre par ordinateur
EP3944108A1 (fr) Révocation de certificats dans une installation technique
EP4181462A1 (fr) Procédé de gestion des certificats pour installations hétérogènes, système informatique et produit-programme informatique
DE102024210000A1 (de) Inbetriebnahme eines Fortbewegungsmittels in der Produktion
WO2026002646A1 (fr) Procédé et dispositif de fourniture et de validation d&#39;informations d&#39;identité de dispositif sécurisées de manière cryptographique

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION HAS BEEN PUBLISHED

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

AX Request for extension of the european patent

Extension state: BA ME

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN

18D Application deemed to be withdrawn

Effective date: 20210925